Safeguard
Vulnerability Analysis

CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability

CVE-2025-49704 affects Microsoft SharePoint and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-22.

Safeguard Research Team
3 min read

CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability

Status: confirmed exploited in the wild

CVE-2025-49704 appears in CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2025-07-22. Inclusion in KEV is not a severity prediction. It means CISA has reliable evidence that the vulnerability has actually been exploited against real targets, which is a stronger signal than a CVSS score on its own.

FieldValue
CVECVE-2025-49704
VendorMicrosoft
ProductSharePoint
Added to KEV2025-07-22
Federal due date2025-07-23
Ransomware campaign useKnown

What the vulnerability is

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.

Weakness classification

CISA classifies this entry under:

Required action

CISA's stated required action for this entry:

Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

Ransomware context

CISA records this vulnerability as known to have been used in ransomware campaigns. That materially raises its priority relative to its CVSS score alone.

Federal remediation deadline

Under CISA Binding Operational Directive 22-01, U.S. federal civilian executive branch agencies were required to remediate this vulnerability by 2025-07-23. The directive does not bind private organisations, but the due date is a useful external signal: CISA sets shorter windows for what it assesses as higher risk.

Why KEV membership changes prioritisation

Most vulnerability backlogs are too large to clear, so the practical question is ordering rather than coverage. KEV is useful for that because it is evidence-based: an entry is on the list because exploitation was observed, not because a scoring formula predicted it might be.

A defensible triage rule used widely is to treat KEV membership as a promotion signal that overrides CVSS ranking, on the basis that a confirmed-exploited medium-severity issue generally warrants attention ahead of a theoretical critical one.

Determining whether you are affected

  1. Establish whether Microsoft SharePoint is present anywhere in your estate, including indirectly and in systems not under active management.
  2. Identify the deployed versions and compare against the vendor advisory linked below.
  3. Apply the required action above, then confirm the change took effect rather than assuming it did.

Step one is where this usually fails. Several of the most costly incidents on record, including Code Red and Log4Shell, turned on organisations being unable to answer whether affected software was present at all.

How Safeguard helps

Safeguard's vulnerability management enriches findings with KEV and EPSS data, so an entry like this one surfaces as confirmed-exploited rather than sitting undifferentiated in a ranked list.

Sources

Catalog data retrieved from CISA KEV version 2026.09.16. Verify against the live catalog before relying on dates for compliance purposes.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.